Advanced Forensic Audit Investigation and Interviewing Training Course
| Course code | SD-A-053 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Auditing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Suspected fraud, financial misconduct, and control override require more than routine audit testing. Investigators must turn an allegation, anomaly, or whistleblower report into a defensible work plan; preserve evidence without contaminating it; analyse transactions at scale; and conduct interviews that obtain reliable information without making unsupported accusations. This course addresses the point at which internal audit, finance, compliance, and investigation teams need to move from identifying red flags to building a fact-based case that can withstand executive, legal, regulatory, or disciplinary scrutiny.
Over five days, participants apply a structured forensic audit methodology from case intake through reporting. They learn to define allegations and investigative hypotheses, assess fraud risks under ISA 240, establish evidence chains of custody, design targeted data tests, use Excel and IDEA for anomaly detection, review documents and digital records, and distinguish corroborated facts from inference. The interviewing modules cover witness preparation, PEACE-based questioning, cognitive interviewing techniques, deception indicators used cautiously, admission-seeking boundaries, and contemporaneous interview documentation.
Instruction combines expert-led briefings with a multi-stage financial misconduct case. Participants work with transaction extracts, emails, invoices, approval records, and interview scenarios to develop an investigation plan, evidence register, data-testing rationale, interview plan, and concise forensic findings report. They leave with a reusable investigation case-file pack and an individual action plan for applying the methods within their organisation. A certificate is awarded on completion.
The course is designed for experienced audit and assurance professionals who already understand financial controls and need stronger investigative, analytical, and interviewing capability for complex or sensitive matters.
Course objectives
By the end of this course, participants will be able to:
- Formulate allegation statements, investigation objectives, and testable fraud hypotheses for a forensic audit case
- Apply ISA 240 fraud-risk principles to prioritise investigative scope, evidence sources, and control-override testing
- Construct an evidence register and chain-of-custody record that preserves source integrity and auditability
- Perform targeted transaction tests in Excel and IDEA to identify duplicates, outliers, split payments, and unusual vendor activity
- Develop a document-review protocol that links invoices, approvals, communications, and financial records to case hypotheses
- Prepare a PEACE-based interview plan with issue sequencing, open questions, exhibits, and corroboration objectives
- Conduct structured fact-finding interviews using active listening, probing, challenge, and contemporaneous note-taking methods
- Produce a defensible forensic findings report that separates facts, analysis, limitations, and recommended actions
Benefits of attending
For you
- Gain a repeatable method for leading investigations from allegation intake through final findings
- Build confidence conducting difficult witness and subject interviews without relying on accusatory questioning
- Strengthen credibility with legal, compliance, and executive stakeholders through defensible evidence handling
- Create stronger audit committee reports by separating verified facts, analytical conclusions, and unresolved limitations
- Expand eligibility for forensic audit, investigations, ethics, and financial-crime assignments
For your organisation
- Reduce the risk of poorly scoped investigations that waste time or miss critical evidence
- Improve preservation and documentation of evidence for disciplinary, legal, or regulatory review
- Detect suspicious payment, vendor, and journal-entry patterns earlier through targeted data testing
- Create more consistent interview practices across audit, compliance, HR, and finance investigations
- Convert investigation findings into specific control remediation priorities and accountable action plans
Target competencies
Who should attend
- Internal Audit Managers — who lead sensitive reviews and need investigations that withstand audit committee scrutiny
- Forensic Auditors — who require stronger evidence, analytics, and interviewing methods for complex cases
- Financial Controllers — who investigate irregular transactions, control overrides, and suspected financial misconduct
- Compliance and Ethics Officers — who manage whistleblower allegations and coordinate fact-finding responses
- Risk Managers — who need to assess fraud exposure and convert investigation findings into control improvements
- External Audit Seniors and Managers — who encounter fraud indicators and need disciplined escalation and evidence techniques
Requirements and prerequisites
Participants should have practical experience in internal audit, external audit, financial control, compliance, or fraud-risk work. They should understand financial statements, transaction cycles, segregation of duties, audit evidence, materiality, and basic audit sampling. Familiarity with Excel formulas, filters, PivotTables, and reviewing invoices or general-ledger extracts is assumed; the course builds from these skills into forensic analysis. Prior experience of conducting investigations or interviews is helpful but not required. Participants do not need legal qualifications, coding skills, prior use of IDEA or Relativity, or specialist digital-forensics experience.
Training methodology
The programme uses instructor-led forensic audit demonstrations, guided data-analysis labs, document-review workshops, and coached interview practice. A running case involving suspected procurement fraud and management override develops across the five days. Participants analyse general-ledger and vendor data in Excel and IDEA, build an evidence register, review simulated communications and approvals, and conduct role-play interviews with observers using structured feedback sheets. Small groups present their findings to a mock investigation steering group, then complete an individual workplace application plan.
Course outline
Day 1: Forensic audit strategy and case control
- Forensic audit versus routine assurance engagement objectives
- Allegation framing and investigation issue trees
- Fraud triangle, fraud diamond, and behavioural red flags
- ISA 240 responsibilities and management override considerations
- Scoping decisions, materiality, and investigative proportionality
- Investigation governance, independence, and conflict-of-interest controls
- Case plans, milestones, decision logs, and escalation protocols
Workshop: Participants convert a whistleblower allegation into a scoped investigation charter, hypothesis matrix, and initial evidence-source map.
Day 2: Evidence preservation and financial data analysis
- Evidence relevance, reliability, authenticity, and admissibility considerations
- Chain-of-custody forms and evidence register design
- General-ledger extraction and data-quality validation procedures
- Excel PivotTables, XLOOKUP, conditional formatting, and duplicate testing
- IDEA functions for gap detection, stratification, and Benford analysis
- Journal-entry testing for override, round amounts, and unusual posting times
- Vendor, payment, and purchase-order anomaly tests
Workshop: Participants analyse a simulated accounts-payable and general-ledger extract to produce a ranked suspicious-transaction schedule with test rationale.
Day 3: Documentary and digital evidence review
- Document-review protocols and coding frameworks
- Invoice, contract, approval, and receiving-record triangulation
- Email chronology construction and communication pattern analysis
- Metadata awareness and preservation boundaries for non-specialists
- Relativity review workflows, tags, searches, and issue coding
- Corroboration matrices linking evidence to investigative hypotheses
- Handling exculpatory evidence and alternative explanations
Workshop: Participants review a case document set and create a chronology, corroboration matrix, and list of evidential gaps requiring follow-up.
Day 4: Forensic interviewing and statement assessment
- Interview objectives, sequencing, and witness prioritisation
- PEACE model phases for investigative interviews
- Cognitive interviewing techniques for recall and detail
- Open, probing, clarifying, and challenge-question design
- Rapport, silence, active listening, and neutral language
- Exhibit presentation and testing statements against evidence
- Contemporaneous notes, interview summaries, and statement validation
Workshop: Participants conduct and observe a role-play witness interview, producing an interview plan, question log, and evidence-linked interview summary.
Day 5: Findings, reporting, and remediation
- Assessing sufficiency of evidence and investigative limitations
- Fact, inference, opinion, and allegation distinctions in reporting
- Forensic report structure for executives, legal counsel, and audit committees
- Quantifying financial exposure, loss, and recovery considerations
- Root-cause analysis of control failure and management override
- Remediation recommendations, ownership, and verification measures
- Investigation closure, record retention, and lessons-learned reviews
Workshop: Participants present a forensic findings report and remediation plan to a mock steering committee, receiving instructor feedback on evidential logic and report clarity.
Tools & standards covered
Microsoft Excel, IDEA Data Analysis, Relativity, ISA 240
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Auditing
COBIT 2019 Control Assessment for IT Auditors Training Course
IT auditors are increasingly asked to assess whether technology controls support reliable financial reporting, protect regulated data, and p…
ISACA ITAF Audit Framework Application Training Course
Technology audit teams are expected to produce work that is defensible to audit committees, regulators, external auditors and senior managem…
Grant Compliance Auditing for NGO Finance Teams Training Course
NGO finance teams must demonstrate that restricted funds were spent for the approved purpose, charged to the correct grant, supported by rel…
SAP Audit Management Reporting and Workflow Training Course
Internal audit teams need timely, defensible reporting without relying on disconnected spreadsheets, email-based review cycles, or manual st…